PT-2026-98890 · Piwigo · Piwigo

CVE-2026-42322

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 16.4.0
Description In the 'admin/themes standard pages.php' endpoint, the application validates uploaded logo content by MIME type but uses the attacker-controlled std pgs logo extension when creating the stored filename. An authenticated administrator can upload image content with a server-executable extension, allowing the file to be stored in a web-accessible directory and executed by the web server. This can lead to arbitrary command execution, data disclosure, modification, persistence, and service disruption.
Recommendations Update to version 16.4.0.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42322
GHSA-7W97-5G4P-XQVV

Affected Products

Piwigo